Citrix NetScaler critical flaw could leak data, update now
2026-03-24T14:51:55Z•cf260d78b87e847748a7d80d710de76034f5de93bfeed42a94bc77b260abc998
Aqua SecurityCVE-2025-62843CVE-2025-62844CVE-2025-62845CVE-2025-62846CVE-2026-21992CVE-2026-3055Citrix NetScalerDocker HubIran-linkedNasir SecurityNorth Korea-linkedOracle Identity ManagerQNAPRussia-linked actors vs messaging apps','Operation Alice','dark‑Signal phishingStoatWaffleTeam 8TeamPCPTelegram C2TrivyVisual Studio CodeWhatsApp phishinginfostealersupply chain
What happened
Multiple high-impact security stories: Citrix issued an urgent patch for a critical NetScaler memory overread (CVE-2026-3055, CVSS 9.3) that can leak sensitive data; Oracle fixed a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8). QNAP addressed four vulnerabilities demonstrated at Pwn2Own (CVE-2025-62843 → CVE-2025-62846). Other incidents include a Trivy/Docker Hub supply-chain compromise that pushed TeamPCP infostealer code and defaced Aqua Security repositories, North Korea-linked actors abusing VS Code auto-run to spread StoatWaffle, Iran- or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cf260d78b87e847748a7d80d710de76034f5de93bfeed42a94bc77b260abc998
- Enrichment time
- 2026-03-24T14:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.